Linux “ssh-keysign-pwn” Flaw Exposing Critical Authentication Files
ID: de2c9223-b752-5242-90ce-21ab5503f0d2
STIX ID: report--de2c9223-b752-5242-90ce-21ab5503f0d2
Feed Name: GBHackers
Threat Score
A newly disclosed Linux kernel race-condition (CVE-2026-46333, 'ssh-keysign-pwn') in ptrace_may_access/dumpability lets unprivileged local attackers hijack open file descriptors during process exit, enabling theft of SSH private keys and exposure of /etc/shadow; a public PoC exists and patches have been released for affected kernels and distributions, so administrators should apply kernel updates or restrict local access until patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
